Legal
Privacy Policy
Last updated: 11 August 2026
1. Who we are
ValarIQ ("we", "us") provides operational control for autonomous payment agents at https://valariq.com. Contact: hello@valariq.com.
2. What we collect
- Account data: name, email address, and password hash when you create a workspace.
- Operational data you enter: agent names, certificates, fingerprints, scopes, API key metadata, approval decisions, and audit events.
- Technical logs: IP address, user agent, and request timestamps needed to operate and secure the service.
We do not require payment card details at this stage. Design-partner billing is handled offline by invoice.
3. How we use data
- Authenticate users and operate workspaces.
- Enforce agent identity, scope constraints, and human authorisation.
- Generate signed evidence packs and audit trails.
- Respond to support and security enquiries.
- Improve reliability and prevent abuse.
4. Legal bases (UK GDPR)
We process personal data under contract (to provide the service you request), legitimate interests (security, product improvement), and where required by law. Where consent is required, we will ask for it.
5. Storage and processors
Application data is stored in encrypted persistent storage on hosted infrastructure (currently Railway). Session secrets and CA material are held on the same persistent volume. We use infrastructure providers as processors solely to host and deliver the service.
6. Retention
Account and operational records are retained while your workspace is active and for a reasonable period afterwards for security, dispute, and audit purposes, unless you request earlier deletion where legally permitted.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and you may object to certain processing. Contact hello@valariq.com. You may also complain to the UK Information Commissioner's Office (ICO).
8. Security
We use HTTPS, hashed passwords, session secrets, scoped API keys, and signed evidence packs. See our Security overview for current controls and roadmap items (including SSO and formal compliance programmes).
9. Changes
We may update this policy as the product matures. Material changes will be reflected on this page with an updated date.